10 Passkey Survival Tips: Prepare for Your Passwordless Future Now | ZDNET

10 Passkey Survival Tips: Prepare for Your Passwordless Future Now | ZDNET

As the digital landscape evolves, the transition to passwordless authentication through passkeys is taking shape, eliminating the need for user IDs and passwords. This shift, led by tech giants within the FIDO Alliance, aims to enhance security by preventing password-related phishing attacks. Users are encouraged to prepare for this change by selecting appropriate credential managers and adapting their security practices accordingly.Affected: Users of online applications and websites, technology companies, FIDO Alliance members

Keypoints :

  • Credential managers, often mistakenly called password managers, will play a crucial role in the passwordless future.
  • There are two main types of credential managers: built-in (from tech giants like Apple, Google, Microsoft) and bring-your-own (BYO) options like 1Password and LastPass.
  • Passkeys differ significantly from passwords, serving as a more secure alternative to vulnerable user ID and password combinations.
  • Users should begin by choosing a BYO credential manager to maintain control over their credentials across multiple platforms.
  • Migrating from one credential manager to another requires careful attention to avoid duplicate entries and conflicts.
  • It’s essential to stop using shared passwords across platforms, as this increases security risks.
  • Consider using a roaming authenticator for added security, storing passkeys on separate devices as a backup.
  • Establish passkeys wherever possible to bolster protection against phishing attacks.
  • Users should name their passkeys if the feature is available to avoid confusion in the credential management process.
  • Continue to retain user IDs and passwords until the passkey infrastructure is fully reliable and universally accepted.
  • When passkeys are not available, implement multi-factor authentication to add layers of security to existing credentials.
  • Always download and save recovery codes offered by sites using multi-factor authentication to ensure account recovery capability.
  • Manage multiple copies of a credential manager across different profiles on the same system to streamline credentials for personal and work use.
  • The transition to passkeys can be challenging, but their benefits need to be embraced as the technology matures.

Read More: https://www.zdnet.com/article/10-passkey-survival-tips-prepare-for-your-passwordless-future-now/